South Korean and U.S. cybersecurity agencies have issued a joint warning regarding the Gunra ransomware, which targets critical infrastructure through exploited Fortinet vulnerabilities and sophisticated double-extortion tactics.
Key Points
- Gunra ransomware has compromised 51 victims globally since April 2025, primarily across South Korea, Brazil, Thailand, Hong Kong, and Spain.
- Attackers gain initial access by exploiting vulnerabilities in Fortinet FortiOS and FortiProxy appliances, specifically CVE-2024-55591 and CVE-2025-24472.
- The group utilizes a double-extortion model, exfiltrating sensitive data before encrypting systems and threatening to publish stolen information if ransoms remain unpaid.
- Technical tactics include using Impacket libraries for lateral movement, credential dumping from domain controllers, and bypassing multi-factor authentication on VDI portals.
- Security researchers have observed potential operational overlaps between Gunra and state-sponsored actors, including the North Korean-linked Lazarus Group.